I don’t understand. your mailcow server has A record for like mail.yourdomain.com
your primary maildomain has MX record for yourdomain.com, pointing to mail.yourdomain.com
Any other mail domain has MX record like otherdomain.com pointing to mail.yourdomain.com
This way, all users can only use webmail via mail.yourdomain.com.
Why did you configure the other SAN (CNAME) for the other domains in the first place, if you do not want the users to use them? They are not necessary.